CSIDB logo
Incident

Neutralinojs

Incident posture

Attack window
Mar 2026
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 06:02

Linked entities

Victim
Neutralinojs
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
2023
Discovered
Mar 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

North Korean threat actors using fake job interviews have compromised software repositories, inserting malicious Visual Studio Code tasks that execute when developers open the projects and accept the workspace trust prompt. The malicious code hides in the .vscode folder, allowing it to spread each time a victim commits changes to GitHub, creating a self‑propagating chain that infected over 750 repositories, including those of DataStax and the Java application provider Neutralinojs, and generated hundreds of malicious task configurations and commit‑tampering instances.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The campaign referred to as 'Contagious Interview' involves North Korean threat actors tracked by Trend Micro as Void Dokkaebi, also known as Famous Chollima, who pose as recruiters from cryptocurrency and AI firms to lure developers into cloning and executing code repositories during fake job interviews. Attackers embed malicious Visual Studio Code tasks and injected code that execute when a victim opens the project in VS Code and accepts the workspace trust prompt, allowing the malware to run without further interaction. Once the victim commits the altered code to GitHub, the hidden .vscode folder containing the malicious task remains concealed, turning the repository into a Trojan horse that infects any subsequent developer who clones it and opens it in VS Code, thereby creating a self‑propagating chain. Each compromised developer seeds new repositories with the infection vector, and each new victim can become a distributor of the malware. In March alone, Trend Micro observed more than 750 infected code repositories, over 500 malicious VS Code task configurations, and 101 instances of the commit‑tampering tool used by Void Dokkaebi.

Repositories belonging to the data management company DataStax and the Java application provider Neutralinojs were identified as carrying infection markers linked to the campaign. The infection markers indicate that the malicious VS Code tasks and associated code had been introduced into those repositories, potentially exposing downstream users to the remote access Trojans and other malware distributed by the actors. Trend Micro’s report detailed the scope of the activity, noting that the campaign had evolved beyond its initial focus on job‑seekers to affect a broader range of software development projects. The report also noted that the attackers systematically targeted developers by exploiting the trust placed in technical assessments during hiring processes.

Trend Micro published the findings in a report released this week, which includes the identification of the infected repositories, the malicious VS Code task configurations, and the commit‑tampering tool instances. The report describes how the abuse of VS Code’s workspace task system enables the malware to propagate without user interaction after the initial trust prompt is accepted. The documentation also notes the observed increase in infection markers across multiple software projects during the March observation period.

Sources

Sources available to members: 1 source.

CSIDB